<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Automation or Innovation?]]></title><description><![CDATA[<p>Automation or Innovation?</p><p>Absorption or Containment?</p><p>"Does AI-assisted vulnerability discovery represent a categorical innovation in offensive cyber capability — a new class of finding previously unreachable by any combination of human and tool — or does it represent the automation and scaling of methods that already existed in the security-research repertoire? </p><p>The policy responses appropriate to each framing diverge sharply."</p><p><a href="https://codeberg.org/tzafaar/Buffers_overflow_into_policy/src/branch/main/briefing%20notes/innovation-or-automation-v5.md" rel="nofollow noopener"><span>https://</span><span>codeberg.org/tzafaar/Buffers_o</span><span>verflow_into_policy/src/branch/main/briefing%20notes/innovation-or-automation-v5.md</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/efaf36cd-5f3e-470e-aa1d-117ced34fcf6/automation-or-innovation</link><generator>RSS for Node</generator><lastBuildDate>Thu, 14 May 2026 23:26:05 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/efaf36cd-5f3e-470e-aa1d-117ced34fcf6.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 11 May 2026 11:36:57 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Automation or Innovation? on Mon, 11 May 2026 22:02:06 GMT]]></title><description><![CDATA[<p><span><a href="/user/meartur%40infosec.exchange">@<span>meartur</span></a></span> fully agree! there must be a measurable "return" to justify any, even negligible, investment. </p><p>The best source i could find on the attacker perspective on this issue was the paper below.</p><p>According to the the paper, attackers will squeeze all the juice out of a working exploit before looking for a new one. Attackers will keep "harvesting" the same field (subset of software) as long as it remains fertile (i love analogies <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title="🙂" alt="🙂" />).</p><p>This was pre-LLM. We may have to wait for some empirical evidence...on modern farming practices.</p><p>Allodi, L., Massacci, F. and Williams, J. (2022), "The Work-Averse Cyberattacker Model: Theory and Evidence from Two Million Attack Signatures." </p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">

<div class="card-body">
<h5 class="card-title">
<a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC9543271/">
Checking your browser - reCAPTCHA
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC9543271/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://pmc.ncbi.nlm.nih.gov/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(pmc.ncbi.nlm.nih.gov)</span></p>
</a>
</div><p></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/aristot73/statuses/116558196040640842</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/aristot73/statuses/116558196040640842</guid><dc:creator><![CDATA[aristot73@infosec.exchange]]></dc:creator><pubDate>Mon, 11 May 2026 22:02:06 GMT</pubDate></item><item><title><![CDATA[Reply to Automation or Innovation? on Mon, 11 May 2026 21:36:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/aristot73%40infosec.exchange">@<span>aristot73</span></a></span> Agreed! I'd add that cost collapse isn't the whole story though. Some searches wouldn't happen at any price because some software/bugs might simply be uninteresting to people.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/meartur/statuses/116558093451880836</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/meartur/statuses/116558093451880836</guid><dc:creator><![CDATA[meartur@infosec.exchange]]></dc:creator><pubDate>Mon, 11 May 2026 21:36:01 GMT</pubDate></item><item><title><![CDATA[Reply to Automation or Innovation? on Mon, 11 May 2026 12:28:01 GMT]]></title><description><![CDATA[<p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/261d.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--point_up" style="height:23px;width:auto;vertical-align:middle" title="☝" alt="☝" />️ <span><a href="/user/meartur%40infosec.exchange">@<span>meartur</span></a></span></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/aristot73/statuses/116555938633565549</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/aristot73/statuses/116555938633565549</guid><dc:creator><![CDATA[aristot73@infosec.exchange]]></dc:creator><pubDate>Mon, 11 May 2026 12:28:01 GMT</pubDate></item></channel></rss>